CVE Database
/

CVE-2009-0940

Back to search

CVE-2009-0940

Published: Mar 18, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network configuration via a NetIPChange request to hp/device/config_result_YesNo.html/config, or (3) change the password via the Password and ConfirmPassword parameters to hp/device/set_config_password.html/config.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2009-0754
vdb-entry
x_refsource_VUPEN
HPSN-2009-001
vendor-advisory
x_refsource_HP
52848
vdb-entry
x_refsource_OSVDB
34143
vdb-entry
x_refsource_BID
52849
vdb-entry
x_refsource_OSVDB
52847
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now